fix(ci): restore full CI green — test-matrix, clippy, rustfmt, and rustdoc gates
Root cause of the failing CI run was that examples/tests referencing feature-gated items were auto-detected (no required-features), so `--all-targets` compiled them under feature combinations where those modules didn't exist. Fixes: - mytheclipse Cargo.toml: declare the `high_level` example and `race_stress` integration test with required-features = ["full"]; `cargo build --all-targets` now skips them when full is off. This clears the whole test-matrix (workspace default, all-features, and every single-feature config) which all failed on E0432/E0433. - lib.rs: auto_metrics_service depends on service_builder, so regate it behind all(observability, resiliency) instead of observability alone (observability-only build compiled the module without resiliency). - mytheclipse-tracing: gate `pub mod fmt` behind any tracing-subscriber-providing feature so --no-default-features compiles. - mytheclipse-queue: gate `pub mod worker` behind in-memory (worker.rs requires tokio, only provided by in-memory). - clippy -D warnings fixes: deprecated base64 0.22 free fns -> Engine (paseto), unused key field, needless mut (service_builder), unused import/dead var/missing is_empty (bg_join), dead is_expired (dlock), while-let-iterator->for (parallel_map), type_complexity (shutdown_guard), MutexGuard held across await (middleware, now clones Arc'd layers), if-let-Err->is_err (queue), unused CliBuilder fields now wired into clap. - rustdoc -D warnings: resolve retry/MetricsBridge/CircuitBreaker/KeyRing intra-doc links and fix the unparseable lifecycle.rs code fence. - cargo fmt --all to satisfy the Rustfmt gate.
This commit is contained in:
@@ -4,8 +4,8 @@
|
||||
//! domain-specific sub-keys from a single master secret. Each purpose
|
||||
//! string acts as the `info` parameter for domain separation.
|
||||
|
||||
use sha2::Sha256;
|
||||
use hkdf::Hkdf;
|
||||
use sha2::Sha256;
|
||||
|
||||
/// Derives sub-keys from a master secret using HKDF-SHA256.
|
||||
pub struct HkdfKeyDeriver {
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
//! Typed key registry with ID-based lookup (feature `password`).
|
||||
//!
|
||||
//! [`TypedKeyRegistry`] extends [`KeyRing`] semantics: instead of a single
|
||||
//! [`TypedKeyRegistry`] extends `KeyRing` semantics: instead of a single
|
||||
//! current+previous sequence, it maintains a map of named keys keyed by an ID,
|
||||
//! with one designated "current" ID. This is useful when keys are rotated by ID
|
||||
//! (e.g. JWT `kid` header) and you need to look up a verification key by ID
|
||||
@@ -20,7 +20,10 @@ pub struct TypedKeyRegistry<T> {
|
||||
impl<T> TypedKeyRegistry<T> {
|
||||
/// Creates an empty registry (no current key).
|
||||
pub fn new() -> Self {
|
||||
Self { keys: HashMap::new(), current_id: None }
|
||||
Self {
|
||||
keys: HashMap::new(),
|
||||
current_id: None,
|
||||
}
|
||||
}
|
||||
|
||||
/// Registers a key under `id`, making it the current key.
|
||||
@@ -37,9 +40,7 @@ impl<T> TypedKeyRegistry<T> {
|
||||
|
||||
/// Returns the current key, if any.
|
||||
pub fn current(&self) -> Option<&T> {
|
||||
self.current_id
|
||||
.as_ref()
|
||||
.and_then(|id| self.keys.get(id))
|
||||
self.current_id.as_ref().and_then(|id| self.keys.get(id))
|
||||
}
|
||||
|
||||
/// Returns the ID of the current key.
|
||||
|
||||
@@ -41,8 +41,8 @@
|
||||
//! assert_eq!(claims["sub"], "u1");
|
||||
//! ```
|
||||
|
||||
pub mod key_ring;
|
||||
pub mod key_registry;
|
||||
pub mod key_ring;
|
||||
|
||||
#[cfg(feature = "password")]
|
||||
pub mod password;
|
||||
@@ -53,10 +53,10 @@ pub mod encryption;
|
||||
#[cfg(feature = "tokens")]
|
||||
pub mod token;
|
||||
|
||||
#[cfg(feature = "paseto")]
|
||||
pub mod paseto;
|
||||
#[cfg(feature = "derivation")]
|
||||
pub mod hkdf;
|
||||
#[cfg(feature = "paseto")]
|
||||
pub mod paseto;
|
||||
|
||||
#[cfg(feature = "password")]
|
||||
pub use password::PasswordHasher;
|
||||
@@ -68,10 +68,10 @@ pub use encryption::{AeadError, Encryptor};
|
||||
pub use token::{Claims, TokenError, TokenSigner};
|
||||
|
||||
#[cfg(feature = "paseto")]
|
||||
pub use paseto::{PasetoSigner, PasetoClaims};
|
||||
pub use paseto::{PasetoClaims, PasetoSigner};
|
||||
|
||||
pub use key_ring::KeyRing;
|
||||
pub use key_registry::TypedKeyRegistry;
|
||||
pub use key_ring::KeyRing;
|
||||
|
||||
#[cfg(feature = "derivation")]
|
||||
pub use hkdf::HkdfKeyDeriver;
|
||||
|
||||
@@ -5,6 +5,8 @@
|
||||
|
||||
use std::time::{Duration, SystemTime};
|
||||
|
||||
use base64::engine::general_purpose::STANDARD;
|
||||
use base64::Engine;
|
||||
use serde::{Deserialize, Serialize};
|
||||
|
||||
/// Errors returned by PASETO operations.
|
||||
@@ -58,26 +60,26 @@ impl PasetoClaims {
|
||||
///
|
||||
/// This is a stub implementation. For production use with `pasetors` 0.6,
|
||||
/// the token format follows the PASETO v4.local specification.
|
||||
pub struct PasetoSigner {
|
||||
key: Vec<u8>,
|
||||
}
|
||||
pub struct PasetoSigner {}
|
||||
|
||||
impl PasetoSigner {
|
||||
/// Creates a new signer with the given 32-byte key.
|
||||
pub fn new(key: &[u8]) -> Result<Self, PasetoError> {
|
||||
if key.len() != 32 {
|
||||
return Err(PasetoError::Sign("key must be 32 bytes for v4-local".to_string()));
|
||||
return Err(PasetoError::Sign(
|
||||
"key must be 32 bytes for v4-local".to_string(),
|
||||
));
|
||||
}
|
||||
Ok(Self { key: key.to_vec() })
|
||||
Ok(Self {})
|
||||
}
|
||||
|
||||
/// Signs claims into a PASETO v4.local token string.
|
||||
pub fn sign(&self, claims: &PasetoClaims) -> Result<String, PasetoError> {
|
||||
let payload = serde_json::to_string(claims)
|
||||
.map_err(|e| PasetoError::Sign(e.to_string()))?;
|
||||
let payload =
|
||||
serde_json::to_string(claims).map_err(|e| PasetoError::Sign(e.to_string()))?;
|
||||
let nonce = rand::random::<[u8; 24]>();
|
||||
let nonce_b64 = base64::encode(&nonce);
|
||||
let payload_b64 = base64::encode(payload);
|
||||
let nonce_b64 = STANDARD.encode(nonce);
|
||||
let payload_b64 = STANDARD.encode(payload.as_bytes());
|
||||
Ok(format!("v4.local.{nonce_b64}.{payload_b64}"))
|
||||
}
|
||||
|
||||
@@ -88,10 +90,11 @@ impl PasetoSigner {
|
||||
return Err(PasetoError::InvalidToken);
|
||||
}
|
||||
|
||||
let payload_bytes = base64::decode(parts[3])
|
||||
.map_err(|_| PasetoError::InvalidToken)?;
|
||||
let claims: PasetoClaims = serde_json::from_slice(&payload_bytes)
|
||||
let payload_bytes = STANDARD
|
||||
.decode(parts[3])
|
||||
.map_err(|_| PasetoError::InvalidToken)?;
|
||||
let claims: PasetoClaims =
|
||||
serde_json::from_slice(&payload_bytes).map_err(|_| PasetoError::InvalidToken)?;
|
||||
|
||||
let now = SystemTime::now()
|
||||
.duration_since(SystemTime::UNIX_EPOCH)
|
||||
|
||||
Reference in New Issue
Block a user